[PATCH v2] Enable -mrop-protect through configure command
Sachin Monga
smonga@linux.ibm.com
Tue Apr 29 19:17:14 GMT 2025
powerpc64le: Add --enable-rop-protection=yes for configure command.
Suffix -mrop-protect to only ppc64le configured builds with ROP.
Flag error when ROP is configured but the compiler is unsupportive.
Add -mno-rop-protect for Power7 specific source files.
Signed-off-by: Sachin Monga <smonga@linux.ibm.com>
---
This patch is reg tested.
Changes from v1:
Fixed whitespace errors.
Makeconfig | 5 ++-
config.make.in | 4 ++
configure | 18 +++++++++
configure.ac | 9 +++++
sysdeps/powerpc/powerpc64/configure | 40 ++++++++++++++++++++
sysdeps/powerpc/powerpc64/configure.ac | 22 +++++++++++
sysdeps/powerpc/powerpc64/multiarch/Makefile | 4 +-
7 files changed, 98 insertions(+), 4 deletions(-)
diff --git a/Makeconfig b/Makeconfig
index a2ea4f6a33..3c70addd1f 100644
--- a/Makeconfig
+++ b/Makeconfig
@@ -1000,7 +1000,7 @@ endif # $(+cflags) == ""
# otherwise require specifying __attribute__ ((nocommon)) on a
# case-by-case basis).
+cflags += $(cflags-cpu) $(+gccwarn) $(+merge-constants) $(+math-flags) \
- $(+stack-protector) -fno-common
+ $(+stack-protector) -fno-common $(cflags-rop)
+gcc-nowarn := -w
# We must filter out elf because the early bootstrap of the dynamic loader
@@ -1169,7 +1169,8 @@ endif
ifndef ASFLAGS
ASFLAGS := $(filter -g% -fdebug-prefix-map=%,$(CFLAGS))
endif
-override ASFLAGS += -Werror=undef $(ASFLAGS-config) $(asflags-cpu)
+override ASFLAGS += -Werror=undef $(ASFLAGS-config) $(asflags-cpu) \
+ $(asflags-rop)
move-if-change = $(SHELL) $(..)scripts/move-if-change
diff --git a/config.make.in b/config.make.in
index 59897eaec2..90e3172394 100644
--- a/config.make.in
+++ b/config.make.in
@@ -38,6 +38,8 @@ config-os = @host_os@
config-sysdirs = @sysnames@
cflags-cpu = @libc_cv_cc_submachine@
asflags-cpu = @libc_cv_cc_submachine@
+cflags-rop = @rop_protection@
+asflags-rop = @rop_protection@
config-extra-cflags = @libc_extra_cflags@
config-extra-cppflags = @libc_extra_cppflags@
@@ -64,6 +66,8 @@ have-fpie = @libc_cv_fpie@
have-ssp = @libc_cv_ssp@
stack-protector = @stack_protector@
no-stack-protector = @no_stack_protector@
+rop-protection = @rop_protection@
+no-rop-protection = @no_rop_protection@
fortify-source = @fortify_source@
no-fortify-source = @no_fortify_source@
have-selinux = @have_selinux@
diff --git a/configure b/configure
index 7cda641fce..ea88ead2d8 100755
--- a/configure
+++ b/configure
@@ -620,6 +620,8 @@ DEFINES
static_nss
profile
libc_cv_multidir
+no_rop_protection
+rop_protection
libc_cv_test_x86_have_amx_tile
test_enable_cet
libc_cv_test_cc_mprefer_vector_width
@@ -805,6 +807,7 @@ enable_hardcoded_path_in_tests
enable_hidden_plt
enable_bind_now
enable_stack_protector
+enable_rop_protection
enable_static_nss
enable_force_install
enable_maintainer_mode
@@ -1478,6 +1481,9 @@ Optional Features:
--enable-stack-protector=[yes|no|all|strong]
Use -fstack-protector[-all|-strong] to detect glibc
buffer overflows
+ --enable-rop-protection=[yes|no]
+ Use --enable-rop-protection[yes|no] to emit ROP
+ instructions
--enable-static-nss build static NSS modules [default=no]
--disable-force-install don't force installation of files from this package,
even if they are older than the installed files
@@ -4616,6 +4622,16 @@ all|yes|no|strong) ;;
*) as_fn_error $? "Not a valid argument for --enable-stack-protector: \"$enable_stack_protector\"" "$LINENO" 5;;
esac
+# Check whether --enable-rop-protection was given.
+if test ${enable_rop_protection+y}
+then :
+ enableval=$enable_rop_protection; enable_rop_protection=$enableval
+else case e in #(
+ e) enable_rop_protection=no ;;
+esac
+fi
+
+
# Check whether --enable-static-nss was given.
if test ${enable_static_nss+y}
then :
@@ -9181,6 +9197,8 @@ have-libgcc_s = $libc_cv_have_libgcc_s"
+
+
# Set the `multidir' variable by grabbing the variable from the compiler.
# We do it once and save the result in a generated makefile.
libc_cv_multidir=`${CC-cc} $CFLAGS $CPPFLAGS -print-multi-directory`
diff --git a/configure.ac b/configure.ac
index 0b0d8875cc..bfd3796f8f 100644
--- a/configure.ac
+++ b/configure.ac
@@ -272,6 +272,13 @@ all|yes|no|strong) ;;
*) AC_MSG_ERROR([Not a valid argument for --enable-stack-protector: "$enable_stack_protector"]);;
esac
+dnl Build glibc with -mrop-protect.
+AC_ARG_ENABLE([rop-protection],
+ AS_HELP_STRING([--enable-rop-protection=@<:@yes|no@:>@],
+ [Use --enable-rop-protection[yes|no] to emit ROP instructions]),
+ [enable_rop_protection=$enableval],
+ [enable_rop_protection=no])
+
dnl On some platforms we cannot use dynamic loading. We must provide
dnl static NSS modules.
AC_ARG_ENABLE([static-nss],
@@ -2078,6 +2085,8 @@ LIBC_CONFIG_VAR([have-libgcc_s], [$libc_cv_have_libgcc_s])
AC_SUBST(libc_cv_test_cc_mprefer_vector_width)
AC_SUBST(test_enable_cet)
AC_SUBST(libc_cv_test_x86_have_amx_tile)
+AC_SUBST(rop_protection)
+AC_SUBST(no_rop_protection)
# Set the `multidir' variable by grabbing the variable from the compiler.
# We do it once and save the result in a generated makefile.
diff --git a/sysdeps/powerpc/powerpc64/configure b/sysdeps/powerpc/powerpc64/configure
index 3e3a83505a..59a1aaa3cc 100644
--- a/sysdeps/powerpc/powerpc64/configure
+++ b/sysdeps/powerpc/powerpc64/configure
@@ -78,3 +78,43 @@ then :
fi
+# If the user enabled ROP protection, then require that the compiler
+# supports the compiler option that enables ROP.
+if test "$enable_rop_protection" = yes; then
+ rop_protection="-mrop-protect"
+ no_rop_protection="-mno-rop-protect"
+ OLD_CFLAGS="$CFLAGS"
+ CFLAGS="$CFLAGS $rop_protection"
+
+{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: checking if the compiler supports -mrop-protect" >&5
+printf %s "checking if the compiler supports -mrop-protect... " >&6; }
+if test ${libc_cv_rop+y}
+then :
+ printf %s "(cached) " >&6
+else case e in #(
+ e)
+ cat confdefs.h - <<_ACEOF >conftest.$ac_ext
+/* end confdefs.h. */
+
+ #ifndef __ROP_PROTECT__
+ #error compiler does not support -mrop-protect
+ #endif
+
+_ACEOF
+if ac_fn_c_try_compile "$LINENO"
+then :
+ libc_cv_rop=yes
+else case e in #(
+ e) libc_cv_rop=no ;;
+esac
+fi
+rm -f core conftest.err conftest.$ac_objext conftest.beam conftest.$ac_ext ;;
+esac
+fi
+{ printf "%s\n" "$as_me:${as_lineno-$LINENO}: result: $libc_cv_rop" >&5
+printf "%s\n" "$libc_cv_rop" >&6; }
+ if test $libc_cv_rop = no; then
+ as_fn_error $? "$CC doesn't support -mrop-protect" "$LINENO" 5
+ fi
+ CFLAGS="$OLD_CFLAGS"
+fi
diff --git a/sysdeps/powerpc/powerpc64/configure.ac b/sysdeps/powerpc/powerpc64/configure.ac
index 225d66ef1a..b9668c465b 100644
--- a/sysdeps/powerpc/powerpc64/configure.ac
+++ b/sysdeps/powerpc/powerpc64/configure.ac
@@ -43,3 +43,25 @@ EOF
rm -rf conftest.*])
AS_IF([test x$libc_cv_ppc64_notoc = xyes],
[AC_DEFINE(USE_PPC64_NOTOC)])
+
+# If the user enabled ROP protection, then require that the compiler
+# supports the compiler option that enables ROP.
+if test "$enable_rop_protection" = yes; then
+ rop_protection="-mrop-protect"
+ no_rop_protection="-mno-rop-protect"
+ OLD_CFLAGS="$CFLAGS"
+ CFLAGS="$CFLAGS $rop_protection"
+ AC_CACHE_CHECK([if the compiler supports -mrop-protect],
+ libc_cv_rop, [
+ AC_COMPILE_IFELSE([AC_LANG_SOURCE([[
+ #ifndef __ROP_PROTECT__
+ #error compiler does not support -mrop-protect
+ #endif
+ ]])],
+ [libc_cv_rop=yes],
+ [libc_cv_rop=no])])
+ if test $libc_cv_rop = no; then
+ AC_MSG_ERROR([$CC doesn't support -mrop-protect])
+ fi
+ CFLAGS="$OLD_CFLAGS"
+fi
diff --git a/sysdeps/powerpc/powerpc64/multiarch/Makefile b/sysdeps/powerpc/powerpc64/multiarch/Makefile
index dc7c5b14ee..304c0d28c7 100644
--- a/sysdeps/powerpc/powerpc64/multiarch/Makefile
+++ b/sysdeps/powerpc/powerpc64/multiarch/Makefile
@@ -38,8 +38,8 @@ sysdep_routines += memchr-power10 memcmp-power10 memcpy-power10 \
stpcpy-power9 strlen-power9 strncpy-power9 stpncpy-power9 \
strlen-power10
endif
-CFLAGS-strncase-power7.c += -mcpu=power7 -funroll-loops
-CFLAGS-strncase_l-power7.c += -mcpu=power7 -funroll-loops
+CFLAGS-strncase-power7.c += -mcpu=power7 -funroll-loops $(no-rop-protection)
+CFLAGS-strncase_l-power7.c += -mcpu=power7 -funroll-loops $(no-rop-protection)
endif
# Called during static initialization
--
2.43.5
More information about the Libc-alpha
mailing list